@LuKePicci, ciao ancora io,scusami ancora, ma con le mie competenze non riesco ad andare oltre.
Ho ip pubblico
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[NET] received packet: from 37.163.232.13[55686] to mio ip[500] (336 bytes)
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) N(HASH_ALG) N(REDIR_SUP) ]
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[IKE] 37.163.232.13 is initiating an IKE_SA
Wed Nov 27 22:58:11 2019 authpriv.info syslog: 07[IKE] 37.163.232.13 is initiating an IKE_SA
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[IKE] remote host is behind NAT
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[IKE] sending cert request for "C=US, O=bla, CN=bla2"
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(HASH_ALG) N(MULT_AUTH) ]
Wed Nov 27 22:58:11 2019 daemon.info syslog: 07[NET] sending packet: from mio ip[500] to 37.163.232.13[55686] (353 bytes)
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[NET] received packet: from 37.163.232.13[55687] to mio ip[4500] (1488 bytes)
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[ENC] parsed IKE_AUTH request 1 [ IDi CERT N(INIT_CONTACT) CERTREQ AUTH CPRQ(ADDR ADDR6 DNS DNS6) N(ESP_TFC_PAD_N) SA TSi TSr N(MOBIKE_SUP) N(NO_ADD_ADDR) N(MULT_AUTH) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] received cert request for "C=US, O=bla, CN=bla2"
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] received end entity cert "C=US, O=bla, CN=bla1"
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] looking for peer configs matching mio ip[%any]...37.163.232.13[C=US, O=bla, CN=bla1]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] selected peer config 'roadwarriorPUBKEY'
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] using trusted ca certificate "C=US, O=bla, CN=bla2"
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] checking certificate status of "C=US, O=bla, CN=bla1"
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] certificate status is not available
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] reached self-signed root ca with a path length of 0
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] using trusted certificate "C=US, O=bla, CN=bla1"
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] authentication of 'C=US, O=bla, CN=bla1' with RSA_EMSA_PKCS1_SHA256 successful
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] received ESP_TFC_PADDING_NOT_SUPPORTED, not using ESPv3 TFC padding
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] peer supports MOBIKE
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] authentication of 'mio ip' (myself) with RSA_EMSA_PKCS1_SHA256 successful
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] IKE_SA roadwarriorPUBKEY[6] established between mio ip[mio ip]...37.163.232.13[C=US, O=bla, CN=bla1]
Wed Nov 27 22:58:12 2019 authpriv.info syslog: 04[IKE] IKE_SA roadwarriorPUBKEY[6] established between mio ip[mio ip]...37.163.232.13[C=US, O=bla, CN=bla1]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] scheduling reauthentication in 10097s
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] maximum IKE_SA lifetime 10637s
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] sending end entity cert "C=US, O=bla, CN=mio ip"
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] peer requested virtual IP %any
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] reassigning offline lease to 'C=US, O=bla, CN=bla1'
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] assigning virtual IP 10.0.1.1 to peer 'C=US, O=bla, CN=bla1'
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] peer requested virtual IP %any6
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] no virtual IP found for %any6 requested by 'C=US, O=bla, CN=bla1'
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] received proposals: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[CFG] configured proposals: ESP:AES_CBC_128/HMAC_SHA1_96/NO_EXT_SEQ, ESP:3DES_CBC/HMAC_SHA1_96/NO_EXT_SEQ, ESP:AES_CBC_128/AES_CBC_192/AES_CBC_256/3DES_CBC/BLOWFISH_CBC_256/HMAC_SHA1_96/AES_XCBC_96/HMAC_MD5_96/NO_EXT_SEQ
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] no acceptable proposal found
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[IKE] failed to establish CHILD_SA, keeping IKE_SA
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH CPRP(ADDR) N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_6_ADDR) N(ADD_6_ADDR) N(ADD_6_ADDR) N(NO_PROP) ]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 04[NET] sending packet: from mio ip[4500] to 37.163.232.13[55687] (1360 bytes)
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[NET] received packet: from 37.163.232.13[55687] to mio ip[4500] (80 bytes)
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[ENC] parsed INFORMATIONAL request 2 [ D ]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[IKE] received DELETE for IKE_SA roadwarriorPUBKEY[6]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[IKE] deleting IKE_SA roadwarriorPUBKEY[6] between mio ip[mio ip]...37.163.232.13[C=US, O=bla, CN=bla1]
Wed Nov 27 22:58:12 2019 authpriv.info syslog: 05[IKE] deleting IKE_SA roadwarriorPUBKEY[6] between mio ip[mio ip]...37.163.232.13[C=US, O=bla, CN=bla1]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[IKE] IKE_SA deleted
Wed Nov 27 22:58:12 2019 authpriv.info syslog: 05[IKE] IKE_SA deleted
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[ENC] generating INFORMATIONAL response 2 [ ]
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[NET] sending packet: from mio ip[4500] to 37.163.232.13[55687] (80 bytes)
Wed Nov 27 22:58:12 2019 daemon.info syslog: 05[CFG] lease 10.0.1.1 by 'C=US, O=bla, CN=bla1' went offline
Wed Nov 27 22:58:19 2019 daemon.warn odhcpd[3489]: A default route is present but there is no public prefix on wl0_2 thus we don't announce a default route!
Questo il mio ipsec.conf
config setup
conn %default
keyexchange=ikev2
conn roadwarriorPUBKEY
left=%any
leftauth=pubkey
leftcert=serverCert.pem
leftid=il mio ip
leftsubnet=0.0.0.0/0,::/0
#leftsendcert=always
right=%any
rightsourceip=10.0.1.0/24
rightauth=pubkey
rightcert=clientCert.pem
#rightauth2=eap-mschapv2
eap_identity=%identity
auto=add
Su firewall e firewall user ho copiato da guida